chore(quality): decode base64 sources, fix latent bugs, set up CI gates - #1
canstralian wants to merge 21 commits into
Conversation
Several tracked source files (.py, .sh, .yaml, .md) were committed as
base64-encoded text, so ruff/shellcheck/yaml parsers could not read them
and CI lint gates were effectively no-ops. Decoded them in place and
fixed the bugs that surfaced once the files were readable:
- import_vectors.sh: ${entry#*:} parameter expansion (was ${entry#:*}
so URL was never extracted), $EXECUTE missing $ prefix, dry-run echo
had unbalanced quotes around $URL.
- adapters/airtable/scope_mapper.py: __main__ guard contained a stray
U+001F byte and an unused os/json import pair.
Tooling baseline:
- pyproject.toml pins ruff (E, F, I, B, UP) and pytest config; the
dashboard subtree is excluded since it is a TS project.
- requirements-dev.txt pins the dev toolchain (ruff, pytest, pyyaml).
- tests/ adds real coverage for AirtableScopeAdapter and the
vectors/redsage contract manifests so the pytest gate is meaningful
instead of "no tests ran".
- .gitignore added at repo root (was missing).
Verified: ruff check . clean, pytest -q -> 5 passed, bash -n on the
shell script clean, both YAML manifests parse.
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (34)
📝 WalkthroughWalkthroughThis PR decodes archived project files and establishes the BugBountyOS foundation: project tooling configuration, system design and contract documentation, central vector registry with the red-sage contract, Airtable scope adapter implementation, YAML-backed MCP server integration, contract validation tests, and cleaned-up vector submodule imports and documentation. ChangesComplete System Initialization
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Analysis CompleteGenerated ECC bundle from 1 commits | Confidence: 55% View Pull Request #2Repository Profile
Changed Files (25)
Top hotspots
Top directories
Likely Future Issues (1)
Suggested Follow-up Work (1)
Copy-ready bodies security: add scanner evidence for adapters/mcp/README.md + adapters/mcp/server.py ## Summary
- Add security scanner or code-scanning evidence for the recently changed security-sensitive surface.
## Why
- Backfill explicit scanner or code-scanning evidence before another security-sensitive change lands on the touched surface.
## Touched paths
- `adapters/mcp/README.md`
- `adapters/mcp/server.py`
## Validation
- Run or add the relevant security scanner, code scanning, secret scanning, or dependency/security review check for the touched surface.
- Attach the scanner output, SARIF/code-scanning result, or focused security regression test to the follow-up PR.
- Confirm the changed auth, billing, webhook, secret-handling, agent, or CI surface has an explicit pass/fail gate.Generated Instincts (17)
After merging, import with: Files
|
There was a problem hiding this comment.
Code Review
This pull request establishes the foundational architecture for BugBountyOS, introducing a vector registry, contract definitions, and an Airtable-based scope adapter. It also includes an MCP server to expose tools like scope checking and vector listing to AI agents, alongside a suite of tests and a vector import utility. Feedback focuses on improving the robustness of the import script by making it idempotent, reducing maintenance overhead by dynamically loading the vector list from the registry manifest, and adopting standard Python package practices instead of manual path manipulation in the test configuration.
| def list_vectors() -> list: | ||
| """Return the current state of the Vector Registry.""" | ||
| return ["dashboard", "pipeline", "storage", "red-sage"] |
There was a problem hiding this comment.
The list of vectors is hardcoded here, which duplicates the registry defined in control-plane/registry/vectors.yaml. This creates a maintenance burden and a risk of the MCP server becoming out of sync with the actual registry. Consider loading this list dynamically from the YAML manifest to ensure consistency.
| for sub in ("adapters/airtable",): | ||
| sys.path.insert(0, str(ROOT / sub)) |
There was a problem hiding this comment.
Manually manipulating sys.path to allow imports is generally discouraged as it can lead to brittle tests and module shadowing issues. A more robust approach would be to treat the adapters directory as a Python package by adding __init__.py files and using absolute or relative imports, or by installing the project in editable mode during development/CI.
- import_vectors.sh: skip subtree add when vectors/$NAME already exists, making the script idempotent (otherwise re-running fails once the vectors are imported). - adapters/mcp/server.py: load the vector list from control-plane/registry/vectors.yaml at call time instead of hardcoding it, so the registry is the single source of truth. - tests: drop sys.path manipulation in conftest; turn adapters/ into a real package (__init__.py) and import via `from adapters.airtable.scope_mapper import AirtableScopeAdapter`. Pytest's rootdir discovery (via pyproject.toml) puts the repo root on sys.path automatically. Verified: ruff clean, pytest 5 passed, dry-run of import_vectors.sh correctly skips all three existing modules.
|
Note Unit test generation is a public access feature. Expect some limitations and changes as we gather feedback and continue to improve it. Generating unit tests... This may take up to 20 minutes. |
|
@openai-code-agent please review |
|
\n## Code Review Summary\n\n**Status:** No Issues Found | **Recommendation:** Merge\n\n \n \n
Files Reviewed (41 files)\n\n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n- \n\nReviewed by nemotron-3-super-120b-a12b-20230311:free · 491,050 tokens |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@adapters/airtable/README.md`:
- Line 13: Update the README table header to match the code by fixing the typo
"Scope Vules" to "Scope Rules" so it aligns with the variable scope_rules_table
= "Scope Rules"; edit the table row that currently reads "| Scope Vules |
Authorization | ✄ Wired |" and replace "Scope Vules" with "Scope Rules".
In `@adapters/mcp/README.md`:
- Line 20: Remove the stray "J" character that appears after the closing code
fence in the README code block; locate the closing triple-backtick (```), delete
the trailing "J" so the fence is immediately followed by a newline, and ensure
the code block is properly closed without any extra characters.
In `@adapters/mcp/server.py`:
- Around line 19-23: The list_vectors() tool currently reads and parses
REGISTRY_PATH with yaml.safe_load without guarding against missing files, I/O
errors, or malformed/unexpected YAML structure; update list_vectors to catch
exceptions from file access (e.g., FileNotFoundError, OSError) and YAML parsing
(yaml.YAMLError), validate that the loaded data is a dict with a "vectors" list
before iterating, and return an empty list (or a sensible default) on error
while logging the exception; reference REGISTRY_PATH, yaml.safe_load, and the
list_vectors() function when adding the try/except, validation checks, and
process/logger calls.
In `@docs/ARCHITECTURE.md`:
- Line 34: The Mermaid edge between nodes E and F uses invalid syntax "E --.
F{Telemetry stable and role proven?}"; replace it with the correct dotted
arrow-with-head syntax "E -.-> F{Telemetry stable and role proven?}" so the
graph renders properly (locate the line containing the tokens E and F in the
ARCHITECTURE.md Mermaid diagram and update the edge string accordingly).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 1b39c299-45f5-4954-85da-5ee8d7623dcf
📒 Files selected for processing (26)
.gitignoreadapters/__init__.pyadapters/airtable/README.mdadapters/airtable/__init__.pyadapters/airtable/scope_mapper.pyadapters/mcp/README.mdadapters/mcp/server.pycontracts/redsage.yamlcontrol-plane/registry/vectors.yamldocs/ARCHITECTURE.mddocs/CONTRACTS.mdimport_vectors.shpyproject.tomlrequirements-dev.txttests/__init__.pytests/test_airtable_scope_mapper.pytests/test_contracts.pyvectors/dashboard/README.mdvectors/pipeline/README.mdvectors/pipeline/app.pyvectors/pipeline/models.pyvectors/pipeline/nlp_processor.pyvectors/pipeline/routes.pyvectors/storage/README.mdvectors/storage/app.pyvectors/storage/routes.py
💤 Files with no reviewable changes (1)
- vectors/pipeline/nlp_processor.py
|
✅ Created PR with unit tests: #5 |
|
Note Unit test generation is a public access feature. Expect some limitations and changes as we gather feedback and continue to improve it. Generating unit tests... This may take up to 20 minutes. |
- adapters/airtable/README.md: fix typo "Scope Vules" -> "Scope Rules"
(the row in the mapping table now matches scope_rules_table in
scope_mapper.py).
- adapters/mcp/README.md: strip stray "J" character after the closing
triple-backtick of the mcpServers JSON example.
- docs/ARCHITECTURE.md: fix invalid Mermaid edge "E --. F{...}" to use
the documented dotted-arrow form "E -.-> F{...}" so the promotion-
flow diagram renders.
- adapters/mcp/server.py: guard list_vectors() against missing /
malformed vectors.yaml (OSError, yaml.YAMLError) and unexpected
structure (KeyError, TypeError); returns an empty list on error so
the MCP server tool stays alive instead of crashing the agent.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@adapters/airtable/README.md`:
- Around line 10-14: Add a single blank line between the "## Current Mapping"
heading and the following table (the block starting with "| Table | Role |
Status |" and rows like "Scope Rules | Authorization | ✄ Wired") so the table is
separated from the heading and satisfies markdown lint rule MD058.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 6144798e-f98b-4839-8ca3-27252ed2022b
📒 Files selected for processing (4)
adapters/airtable/README.mdadapters/mcp/README.mdadapters/mcp/server.pydocs/ARCHITECTURE.md
✅ Files skipped from review due to trivial changes (2)
- docs/ARCHITECTURE.md
- adapters/mcp/README.md
🚧 Files skipped from review as they are similar to previous changes (1)
- adapters/mcp/server.py
Satisfies markdown lint MD058 in the Current Mapping section of adapters/airtable/README.md.
|
✅ Created PR with unit tests: #7 |
Conflict resolution: - .gitignore: merged both sides - adapters/airtable/scope_mapper.py: kept decoded modern syntax from PR - control-plane/registry/vectors.yaml: decoded format + all 7 vectors from main - contracts: new vectors from main preserved - tests: repo structure tests from main preserved
New dashboard UI components, pages, and config from main branch.
Resolved 7 merge conflicts and synced core files from main: - .gitignore: kept PR's venv/env entries - scope_mapper.py: kept typing import from main - server.py: kept PR's dynamic YAML-based list_vectors - vectors.yaml: preferred decoded YAML from PR over base64 from main - import_vectors.sh: preserved 'already exists' guard - Added pyproject.toml and requirements-dev.txt from main
|
|
||
|
|
||
| _PII_PATTERNS: List[tuple[re.Pattern, str]] = [ | ||
| (re.compile(r"\b\d{3}[-.}?\d{2}[-.]?\d{4}\b"), "ssn"), |
Summary
Code-quality baseline pass. Several source files (
*.py,*.sh,*.yaml,*.md) were committed as base64-encoded text, which meantruff,shellcheck, and YAML parsers couldn't read them — CI's lint gates were effectively no-ops, and bugs hiding inside the encoded blobs went unnoticed.This PR decodes those files in place, fixes the bugs that surfaced, and stands up real lint/test gates.
Decoded files (12)
import_vectors.shadapters/airtable/scope_mapper.py,adapters/airtable/README.mdadapters/mcp/server.py,adapters/mcp/README.mdcontracts/redsage.yamlcontrol-plane/registry/vectors.yamldocs/ARCHITECTURE.md,docs/CONTRACTS.mdvectors/{dashboard,pipeline,storage}/README.mdBugs fixed (only visible after decoding)
import_vectors.shURL="${entry#:*}"→${entry#*:}(URL was never extracted from thename:urlentry)[ "EXECUTE" -eq 1 ]→[ "$EXECUTE" -eq 1 ](missing$— branch never taken)$URLadapters/airtable/scope_mapper.py__main__guard contained a strayU+001Fbyte ("__main\x1f_") — module wouldn't self-runos/jsonimportsTooling baseline
pyproject.toml— pinsruff(E, F, I, B, UP) and pytest config; excludesvectors/dashboard(TS subtree).requirements-dev.txt— pinsruff,pytest,pyyaml.tests/— real coverage forAirtableScopeAdapterplus contract-shape tests forvectors.yamlandredsage.yaml. Thepytestgate is no longer a "no tests ran" no-op..gitignore— added at repo root (was missing).Test plan
ruff check .— cleanpytest -q— 5 passedbash -n import_vectors.sh— cleanyaml.safe_loadci.yml,lint.yml,tests.yml) green on this branchhttps://claude.ai/code/session_01KH2J1ZAZuaSo3B3YEPiVw2
Generated by Claude Code
Summary by CodeRabbit
Release Notes
New Features
Documentation
Tests
Chores